vendor:
Vox TG790 ADSL Router
by:
Cakes
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Vox TG790 ADSL Router
Affected Version From: 6.2.W.1
Affected Version To: 6.2.W.1
Patch Exists: NO
Related CWE: N/A
CPE: h:vox:tg790_adsl_router
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Vox TG790 ADSL Router – Cross-Site Scripting
Due to improper user input management low privilege users are able to create a persistent Cross-Site scripting attack via the phone book function. The PoC involves sending a POST request with malicious JavaScript code to the router. The response will contain the malicious code, which will be executed in the browser.
Mitigation:
Input validation should be used to prevent malicious code from being executed.